Input validation vulnerability in BEAR – Bulk Editor and Products Manager Professional for WooCommerce by Pluginus.Net 1.1.3.3

The BEAR plugin for WordPress is not secure in versions up to, and including, 1.1.3.3. Attackers who have not been authorized can delete profiles by sending a fake request, as long as they can get an administrator to do something such as clicking on a link. This is because the delete_profile function does not have enough security features to protect it.

Detected in:

This information is sourced from www.wpvulnerability.com. An open-source database of vulnerabilities maintained by the community. Help us out by submitting vulnerabilities!

Version compare shows which versions have a vulnerability. For example: >= 2.2.8 <= 2.2.21 means:

> from 2.2.8
= including 2.2.8 & 2.2.21
< to 2.2.21

Is this information incorrect? Please leave us a message.